Cross-Site Scripting Vulnerability in Standard Notes by Evernote and Google Keep
CVE-2026-78325

6.9MEDIUM

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-78325?

A cross-site scripting vulnerability exists in the note importers of Standard Notes for Android, specifically versions up to 3.201.24. This flaw allows attackers to execute arbitrary JavaScript when a user imports specially crafted .enex or Google Keep HTML files. Exploiting this vulnerability can lead to the theft of sensitive information, including encryption keys and note data, and the potential for unauthorized invocation of native device APIs. Users should be aware of the risks associated with importing unverified note files to mitigate potential threats.

Affected Version(s)

Standard Notes Android 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luca Regne, https://regne.me/
.